This Privacy Policy explains how bandsandthat.com collects, uses, stores and shares personal data when individuals visit the website, create a profile, manage their communication preferences, or otherwise interact with the platform.
By using bandsandthat.com, users acknowledge that basic information about their visits to the website may be collected for legitimate interests such as website security, performance monitoring, fraud prevention, troubleshooting and website optimisation.
Who controls your data
bandsandthat.com is the controller of the personal data described in this Privacy Policy, except where this policy states that another party acts as an independent controller. Users can contact bandsandthat.com about privacy matters, complaints, data requests, or deletion requests at hello@bandsandthat.com.
Personal data collected
bandsandthat.com may collect and process the following categories of personal data:
- Account and profile information, such as name, username, email address, password, profile details, biography, images, music or creative content uploaded to a profile, location, and any preferences a user chooses to add.
- Communication preference data, such as whether a user has agreed to receive service emails, content emails, marketing emails, third-party communications, SMS marketing or WhatsApp marketing.
- Contact details, including phone number where a user chooses to add one to receive SMS or WhatsApp communications.
- Technical and usage data, such as IP address, browser type, device information, pages viewed, timestamps, referring URLs, and approximate location derived from IP address.
- User-generated content and interaction data, including messages, support queries, reports, submissions, and other information provided through the website.
How data is used
bandsandthat.com may use personal data for the following purposes:
- To create, maintain and administer user accounts and profiles.
- To provide the core functionality of the website and related services.
- To send service-related communications necessary for account creation, authentication, security and other important administrative matters.
- To send content emails and marketing emails where a user has actively agreed to receive them.
- To allow users to opt in to receiving communications from selected third parties.
- To send SMS or WhatsApp marketing where a user has chosen to add a phone number and has actively opted in.
- To analyse how the website is used, improve user experience, monitor performance and optimise the website.
- To protect the website, users and business operations against misuse, fraud, abuse and other unlawful activity.
- To comply with legal obligations and to establish, exercise or defend legal claims.
Lawful bases
bandsandthat.com relies on one or more lawful bases under UK GDPR depending on the activity:
- Contract: where processing is necessary to create and manage a user account and deliver the services requested by the user.
- Legitimate interests: where processing is necessary to keep the website secure, prevent misuse, improve and optimise the service, and maintain records.
- Consent: where a user chooses to receive marketing emails, content emails, selected third-party communications, SMS marketing or WhatsApp marketing.
- Legal obligation: where processing is needed to comply with applicable laws, lawful requests, or regulatory requirements.
Marketing communications
When signing up for a profile, users may be given the opportunity to agree to receive marketing emails, service emails, content emails, communications from third parties, SMS marketing or WhatsApp marketing.
Users can opt out of marketing or content emails at any time by using the unsubscribe link in the relevant message, changing their communication settings in their account, or contacting hello@bandsandthat.com.
If a user no longer wishes to receive emails connected with their profile, they may also request deletion of their account and associated personal data by emailing hello@bandsandthat.com.
Tracking and analytics
bandsandthat.com may use basic analytics, logs, cookies or similar technologies to understand website visits and interactions for legitimate purposes such as website optimisation, security, diagnostics and service improvement.
Sharing personal data
bandsandthat.com may share personal data with:
- Service providers who help host, maintain, analyse, secure or support the website.
- Professional advisers, insurers, auditors and legal representatives where necessary.
- Regulators, law enforcement bodies, courts or public authorities where legally required.
- Third parties selected by the user where the user has opted in to receive third-party communications.
- A buyer, investor or successor organisation in connection with a business sale, merger or restructuring, subject to appropriate safeguards.
International transfers
If personal data is transferred outside the UK, bandsandthat.com will take steps to ensure the data is protected through appropriate safeguards as required under UK data protection law.
Data retention
Personal data will be kept only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to maintain accounts, provide services, comply with legal obligations, resolve disputes, enforce agreements and protect legal rights.
Data security
bandsandthat.com will use appropriate technical and organisational measures to help protect personal data against unauthorised access, loss, misuse, disclosure or alteration.
Your rights
Subject to applicable law, you may have the right to:
- Request access to the personal data held about you.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of your personal data.
- Request restriction of processing.
- Object to processing carried out on the basis of legitimate interests.
- Withdraw consent at any time where processing is based on consent.
- Request portability of certain data.
- Lodge a complaint with the Information Commissioner's Office (ICO).
To exercise any of these rights, contact hello@bandsandthat.com.
Complaints
Any privacy-related complaint, concern, or request should be sent to hello@bandsandthat.com in the first instance. You also have the right to complain to the Information Commissioner's Office if you believe your personal data has been handled unlawfully or unfairly.
Children's data
bandsandthat.com is not intended for children unless expressly stated otherwise. If bandsandthat.com becomes aware that it has collected personal data from a child in breach of applicable law, it will take appropriate steps to delete that information.
Changes to this policy
bandsandthat.com may update this Privacy Policy from time to time, and any updated version will be posted on the website with a revised effective date.
Governing law
This Privacy Policy, and any dispute or claim arising out of or in connection with it or the use of bandsandthat.com, shall be governed by and construed in accordance with the laws of England and Wales.